[Git][security-tracker-team/security-tracker][master] One CVE got assigned for pcre2 issue
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 08:27:04 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b5b5adf6 by Salvatore Bonaccorso at 2026-09-05T09:26:30+02:00
One CVE got assigned for pcre2 issue
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -10,8 +10,6 @@ CVE-2026-8623 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, PD
NOT-FOR-US: WordPress plugin
CVE-2026-8447 (IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site ...)
NOT-FOR-US: IBM
-CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)
- TODO: check
CVE-2026-86144 (In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclu ...)
TODO: check
CVE-2026-86143 (In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...)
@@ -5467,10 +5465,9 @@ CVE-2026-XXXX [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_
[bookworm] - pcre2 10.42-1+deb12u1
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3 (pcre2-10.48-RC1)
-CVE-2026-XXXX [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit]
+CVE-2026-86145 [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit]
- pcre2 10.48-1
[trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
- [bookworm] - pcre2 10.42-1+deb12u1
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135 (pcre2-10.48)
CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() after JIT fallback with invalid UTF]
=====================================
data/DLA/list
=====================================
@@ -1,4 +1,5 @@
[04 Sep 2026] DLA-4772-1 pcre2 - security update
+ {CVE-2026-86145}
[bookworm] - pcre2 10.42-1+deb12u1
[04 Sep 2026] DLA-4771-1 chromium - security update
{CVE-2026-78891 CVE-2026-78892 CVE-2026-78893 CVE-2026-78894 CVE-2026-78895 CVE-2026-78896 CVE-2026-78897 CVE-2026-78898 CVE-2026-78899 CVE-2026-78900 CVE-2026-78901 CVE-2026-78903 CVE-2026-78904 CVE-2026-78905 CVE-2026-78906 CVE-2026-78907 CVE-2026-78908 CVE-2026-78909 CVE-2026-78910 CVE-2026-78911 CVE-2026-78912 CVE-2026-78913 CVE-2026-78914 CVE-2026-78915 CVE-2026-78934 CVE-2026-78935 CVE-2026-78936 CVE-2026-78937 CVE-2026-78938 CVE-2026-78939 CVE-2026-78940 CVE-2026-78941 CVE-2026-78942 CVE-2026-78943 CVE-2026-78944 CVE-2026-78945 CVE-2026-78946 CVE-2026-78947 CVE-2026-78948 CVE-2026-78949 CVE-2026-78950 CVE-2026-78951 CVE-2026-78952 CVE-2026-78953 CVE-2026-78954 CVE-2026-78955 CVE-2026-78956 CVE-2026-78957 CVE-2026-78958 CVE-2026-78959 CVE-2026-78960 CVE-2026-78961 CVE-2026-78962 CVE-2026-78963 CVE-2026-78964 CVE-2026-78965 CVE-2026-78966 CVE-2026-78967 CVE-2026-78968 CVE-2026-78969 CVE-2026-78974 CVE-2026-78975 CVE-2026-78976 CVE-2026-78977 CVE-2026-78978 CVE-2026-78979 CVE-2026-78980 CVE-2026-78981 CVE-2026-78983 CVE-2026-78984 CVE-2026-78985 CVE-2026-78986 CVE-2026-78987 CVE-2026-78989 CVE-2026-78990 CVE-2026-78991 CVE-2026-78999 CVE-2026-79000 CVE-2026-79001 CVE-2026-79002 CVE-2026-79003 CVE-2026-79004 CVE-2026-79005 CVE-2026-79006 CVE-2026-79007 CVE-2026-79008 CVE-2026-79009 CVE-2026-79010 CVE-2026-79011 CVE-2026-79012 CVE-2026-79013 CVE-2026-79014 CVE-2026-79015 CVE-2026-79016 CVE-2026-79017 CVE-2026-79018 CVE-2026-79019 CVE-2026-79020 CVE-2026-79021 CVE-2026-79022 CVE-2026-79023 CVE-2026-79024 CVE-2026-79025 CVE-2026-79026 CVE-2026-79027 CVE-2026-79028 CVE-2026-79030 CVE-2026-79031 CVE-2026-79032 CVE-2026-79033 CVE-2026-79034 CVE-2026-79038 CVE-2026-79039 CVE-2026-79040 CVE-2026-79041 CVE-2026-79042 CVE-2026-79043 CVE-2026-79044 CVE-2026-79045 CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 CVE-2026-79049 CVE-2026-79050 CVE-2026-79051 CVE-2026-79052 CVE-2026-79053 CVE-2026-79054 CVE-2026-79055 CVE-2026-79056 CVE-2026-79057 CVE-2026-79058 CVE-2026-79059 CVE-2026-79060 CVE-2026-79064 CVE-2026-79065 CVE-2026-79066 CVE-2026-79067 CVE-2026-79068 CVE-2026-79069 CVE-2026-79070 CVE-2026-79071 CVE-2026-79072 CVE-2026-79073 CVE-2026-79074 CVE-2026-79075 CVE-2026-79076 CVE-2026-79077 CVE-2026-79078 CVE-2026-79082 CVE-2026-79083 CVE-2026-79084 CVE-2026-79085 CVE-2026-79086 CVE-2026-79087 CVE-2026-79088 CVE-2026-79089 CVE-2026-79090 CVE-2026-79091 CVE-2026-79093 CVE-2026-79094 CVE-2026-79095 CVE-2026-79097 CVE-2026-79098 CVE-2026-79099 CVE-2026-79103 CVE-2026-79104 CVE-2026-79105 CVE-2026-79106 CVE-2026-79107 CVE-2026-79108 CVE-2026-79109 CVE-2026-79110 CVE-2026-79111 CVE-2026-79112 CVE-2026-79116 CVE-2026-79117 CVE-2026-79118 CVE-2026-79119 CVE-2026-79120 CVE-2026-79121 CVE-2026-79122 CVE-2026-79123 CVE-2026-79124 CVE-2026-79125 CVE-2026-79126 CVE-2026-79127 CVE-2026-79128 CVE-2026-79129 CVE-2026-79130 CVE-2026-79131 CVE-2026-79132 CVE-2026-79133 CVE-2026-79134 CVE-2026-79136 CVE-2026-79137 CVE-2026-79138 CVE-2026-79139 CVE-2026-79140 CVE-2026-79141 CVE-2026-79142 CVE-2026-79143 CVE-2026-79144 CVE-2026-79146 CVE-2026-79147 CVE-2026-79148 CVE-2026-79149 CVE-2026-79150 CVE-2026-79151 CVE-2026-79152 CVE-2026-79154 CVE-2026-79155 CVE-2026-79173 CVE-2026-79174 CVE-2026-79175 CVE-2026-79176 CVE-2026-79177 CVE-2026-79178 CVE-2026-79179 CVE-2026-79180 CVE-2026-79181 CVE-2026-79182 CVE-2026-79183 CVE-2026-79184 CVE-2026-79185 CVE-2026-79186 CVE-2026-79187 CVE-2026-79188 CVE-2026-79189 CVE-2026-79190 CVE-2026-79191 CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79195 CVE-2026-79196 CVE-2026-79197 CVE-2026-79198 CVE-2026-79199 CVE-2026-79200 CVE-2026-79201 CVE-2026-79202 CVE-2026-79203 CVE-2026-79204 CVE-2026-79205 CVE-2026-79206 CVE-2026-79207 CVE-2026-79208 CVE-2026-79209 CVE-2026-79210 CVE-2026-79211 CVE-2026-79212 CVE-2026-79213 CVE-2026-79214 CVE-2026-79215 CVE-2026-79216 CVE-2026-79217 CVE-2026-79218 CVE-2026-79219 CVE-2026-79220 CVE-2026-79221 CVE-2026-79222 CVE-2026-79223 CVE-2026-79224 CVE-2026-79225 CVE-2026-79226 CVE-2026-79227 CVE-2026-79228 CVE-2026-79229 CVE-2026-79230 CVE-2026-79231 CVE-2026-79232 CVE-2026-79233 CVE-2026-79234 CVE-2026-79235 CVE-2026-79236 CVE-2026-79237 CVE-2026-79238 CVE-2026-79239 CVE-2026-79240 CVE-2026-79241 CVE-2026-79242 CVE-2026-79243 CVE-2026-79244 CVE-2026-79245 CVE-2026-79246 CVE-2026-79247 CVE-2026-79248 CVE-2026-79249 CVE-2026-79250 CVE-2026-79251 CVE-2026-79252 CVE-2026-79253 CVE-2026-79254 CVE-2026-79255 CVE-2026-79256 CVE-2026-79257 CVE-2026-79258 CVE-2026-79259 CVE-2026-79260 CVE-2026-79261 CVE-2026-79262 CVE-2026-79263 CVE-2026-79264 CVE-2026-79265 CVE-2026-79266 CVE-2026-79267 CVE-2026-79269 CVE-2026-79270 CVE-2026-79271 CVE-2026-79272 CVE-2026-79273 CVE-2026-79274 CVE-2026-79275 CVE-2026-79276 CVE-2026-79282 CVE-2026-79283 CVE-2026-79284 CVE-2026-79285 CVE-2026-79286 CVE-2026-79287 CVE-2026-79288 CVE-2026-79289 CVE-2026-79290 CVE-2026-79291 CVE-2026-79292 CVE-2026-79293 CVE-2026-84323 CVE-2026-84324 CVE-2026-84325 CVE-2026-84326 CVE-2026-84327 CVE-2026-84328 CVE-2026-84329 CVE-2026-84330 CVE-2026-84331 CVE-2026-84332 CVE-2026-84333 CVE-2026-84334 CVE-2026-84335 CVE-2026-84347 CVE-2026-84348 CVE-2026-84349 CVE-2026-84350 CVE-2026-84351 CVE-2026-84352 CVE-2026-84353 CVE-2026-84354 CVE-2026-84355 CVE-2026-84356 CVE-2026-84357 CVE-2026-84358 CVE-2026-84359}
=====================================
data/next-point-update.txt
=====================================
@@ -558,7 +558,7 @@ CVE-2026-XXXX [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in pcre2_compile_32(
[trixie] - pcre2 10.46-1~deb13u2
CVE-2026-XXXX [GHSA-9qww-pwc4-77qq: PCRE2: out-of-bounds reads in pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF]
[trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-XXXX [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems]
+CVE-2026-86145 [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems]
[trixie] - pcre2 10.46-1~deb13u2
CVE-2026-XXXX [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit]
[trixie] - pcre2 10.46-1~deb13u2
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b5b5adf643c56a34b44a4c449b96596a96e42c43
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b5b5adf643c56a34b44a4c449b96596a96e42c43
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/9f6df78f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list